US12556527B2ActiveUtilityA1

PACS modification to incorporate LACS authentication

Assignee: ASSA ABLOY ABPriority: Apr 8, 2021Filed: Apr 8, 2021Granted: Feb 17, 2026
Est. expiryApr 8, 2041(~14.7 yrs left)· nominal 20-yr term from priority
H04W 12/08H04L 63/0823G07C 2009/00412G07C 2209/63G07C 2009/00468G07C 2009/00436G07C 2009/0042G07C 9/27H04W 12/63H04W 12/069G07C 9/00309H04L 63/0807
45
PatentIndex Score
0
Cited by
27
References
20
Claims

Abstract

A method of integrating a logical access control system with a physical access control system is disclosed. A soft token is received at a hardware accessory from a client device of a user. The soft token includes a payload. The payload includes information about the user that is stored in a user profile of the logical access control system. Based on a verifying of the soft token using a certificate extracted from a trust store of the hardware accessory, the information about the user that is included in the payload is parsed. Based on the information about the user satisfying one or more access criteria of a reader associated with a physical access control system, the reader is triggered. The triggering includes emulating a transaction associated with the physical access control system.

Claims

exact text as granted — not AI-modified
The invention claimed is: 
     
         1 . A system comprising:
 one or more computer processors;   one or more computer memories;   a set of instructions incorporated into the one or more computer memories, the set of instructions configuring the one or more computer processors to perform operations, the operations comprising, at a hardware accessory:   receiving a soft token from a client device of a user, the soft token having been generated or received at the client device based on an accessing of a logical profile of the user by the client device via one or more services of a logical access control system, the soft token including a payload, the payload including information about the user that is stored in the logical profile, the soft token being a JWE token that is decrypted using a private RSA key stored in a secure element of the hardware accessory;   based on a verifying of the soft token using a certificate extracted from a trust store of the hardware accessory, parsing the information about the user that is included in the payload; and   based on the information about the user satisfying one or more access criteria of a reader associated with a physical access control system, triggering the reader, the triggering including emulating a transaction associated with the physical access control system.   
     
     
         2 . The system of  claim 1 , wherein the information about the user includes a role of the user. 
     
     
         3 . The system of  claim 1 , wherein the information about the user includes a credential of the user, the credential associated with a smart card of the physical access control system, the smart card having been assigned to the user. 
     
     
         4 . The system of  claim 3 , wherein the emulating of the transaction includes sending the credential to the reader over a secure connection in a format that is compatible with the physical access control system. 
     
     
         5 . The system of  claim 4 , wherein the secure connection is a near field communication (NFC), Bluetooth connection, or other wireless connection. 
     
     
         6 . The system of  claim 3 , wherein the credential is sent to the reader as a single object. 
     
     
         7 . The system of  claim 6 , wherein the single object is a Secure Identity Object (SIO). 
     
     
         8 . The system of  claim 1 , wherein the transaction is a Seos transaction. 
     
     
         9 . The system of  claim 1 , wherein the soft token is a JWT token. 
     
     
         10 . The system of  claim 1 , wherein the operations further comprise:
 creating a logical association between the reader, the hardware accessory, and a client ID of the hardware accessory during a configuration phase, the creating of the logical association including simultaneously provisioning a public certificate, generating the private RSA key, and registering the client ID, the logical association resulting in the hardware accessory being represented as an element of a LACS, the hardware accessory being an element of a PACS; and   decrypting the JWE using the private RSA key.   
     
     
         11 . The system of  claim 10 , wherein the registering of the client ID for the hardware accessory includes using a dynamic Open ID Connect client registration POST request, the POST request including a scope definition that defines a new scope or an existing scope, the scope definition allowing a client application to request a soft token based on the scope definition. 
     
     
         12 . The system of  claim 10 , further comprising communicating the logical association to the client device for transmission to the logical access control system for storing in a persistence layer of the logical access control system. 
     
     
         13 . A method comprising:
 receiving a soft token from a client device of a user, the soft token having been generated or received at the client device based on an accessing of a logical profile of the user by the client device via one or more services of a logical access control system, the soft token including a payload, the payload including information about the user that is stored in the logical profile, the soft token being a JWE token that is decrypted using a private RSA key stored in a secure element of a hardware accessory;   based on a verifying of the soft token using a certificate extracted from a trust store of the hardware accessory, parsing the information about the user that is included in the payload; and   based on the information about the user satisfying one or more access criteria of a reader associated with a physical access control system, triggering the reader, the triggering including emulating a transaction associated with the physical access control system.   
     
     
         14 . The method of  claim 13 , wherein the information about the user includes a role or a group of the user. 
     
     
         15 . The method of  claim 13 , wherein the information about the user includes a credential of the user, the credential associated with a smart card of the physical access control system, the smart card having been assigned to the user. 
     
     
         16 . The method of  claim 15 , wherein the emulating of the transaction includes sending the credential to the reader over a secure connection in a format that is compatible with the physical access control system. 
     
     
         17 . The method of  claim 13 , further comprising:
 creating a logical association between the reader, the hardware accessory, and a client ID of the hardware accessory during a configuration phase, the creating of the logical association including simultaneously provisioning a public certificate, generating a private RSA key, and registering the client ID; and   decrypting the JWE token using the private RSA key.   
     
     
         18 . A non-transitory machine-readable medium storing a plurality of instructions that, when implemented by one or more computer processors, cause the one or more computer processors to perform operations, the operations comprising:
 receiving a soft token from a client device of a user, the soft token having been generated or received at the client device based on an accessing of a logical profile of the user by the client device via one or more services of a logical access control system, the soft token including a payload, the payload including information about the user that is stored in the logical profile, the soft token being a JWE token that is decrypted using a private RSA key stored in a secure element of a hardware accessory;   based on a verifying of the soft token using a certificate extracted from a trust store of the hardware accessory, parsing the information about the user that is included in the payload; and   based on the information about the user satisfying one or more access criteria of a reader associated with a physical access control system, triggering the reader, the triggering including emulating a transaction associated with the physical access control system.   
     
     
         19 . The non-transitory machine-readable medium of  claim 18 , wherein the information about the user includes a role of the user. 
     
     
         20 . The non-transitory machine-readable medium of  claim 18 , wherein the information about the user includes a credential of the user, the credential associated with a smart card of the physical access control system, the smart card having been assigned to the user.

Join the waitlist — get patent alerts

Track US12556527B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.